4 ms·
Another interesting point they mention is "recovering years long deleted texts." Consider the filesystem your phone uses for volumes it's writing data to and ho
by drvdevd 10y ago
Another interesting point they mention is "recovering years long deleted texts." Consider the filesystem your phone uses for volumes it's writing data to and how it (probably just) unlinks files when deleted... [edit] and I should add a 'factory reset' will probably just write a new filesystem table over the old on disk without wiping anything on most devices
- jdironman 10y agoWhat about doing a factory reset, then use the 'encrypt device' option, then doing another factory reset. Would that provide an extra measure? Unless, of course, the data in it's final state before the final factory reset is un-encrypted.
- drvdevd 10y agoOf course it depends on the phone. Many qualcomm based Android devices seem to have had their Full Disk Encryption scheme broken at the moment [1], for example. But either way, if your disk encryption scheme doesn't fully wipe the disk before use, then any data that ever hit the disk unencrypted could still possibly be sitting there until its physical blocks are consumed (or could be in a cache somewhere). Again this also depends on the hardware, in this case the storage hardware itself. SSDs using TRIM can wipe unused, unencrypted blocks for example in some scenarios. Who knows about the particular functioning of some SD type controller in a phone or even the card's own embedded OS [2]. I would say if you have data on your smartphone you don't want recoverable at rest, take module0000's advice, then also use encryption, and then also use a multi-pass wipe tool on particluar files. Of course all of this could still not work. For example, I'm not sure what the forensic ramifications of a seemingly more complex filesystem like APFS will be in the near future when it hits iOS. [1] https://bits-please.blogspot.com/2016/06/extracting-qualcomms-keymaster-keys.html https://bits-please.blogspot.com/2016/06/extracting-qualcomm... [2] https://www.bunniestudios.com/blog/?p=3554 https://www.bunniestudios.com/blog/?p=3554
- drvdevd 10y agoActually, after re-reading your scheme it doesn't sound too bad either... the main problem would seem to be then if the encryption was fundamentally broken (ie: if the encrypted bits are recoverable after the second factory reset and could then be decrypted)
- eridius 10y agoOn devices with full-disk encryption (such as iPhones made in the past few years), a "factory reset" is equivalent to scrambling the entire disk. This is because it securely erases the keys that were used for all the data on the disk, and without the keys, all that data is effectively random garbage.